
ALYCON-Threat-Landscape
Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Training-free anomaly detection framework using Shannon Entropy, Fisher Information, and Wasserstein Distance to map system states into geometrically…

Splunk detection writeup for CVE-2026-54121 (CertiGhost): AD CS certificate chase abuse leading to full domain compromise. Lab-validated detection,…

Zeek package to detect Zerologon

Framework for implementing Network Intrusion Detection Systems (NIDS) aimed at identifying anomalies in network flows using Federated Learning models.

AIEngine is a next generation interactive/programmable Python/Ruby/Java/Lua and Go NIDS (Network intrusion detection system).

Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.

Zeek package for detecting CVE-2020-1350 (SIGRed) Windows DNS server exploit attempts via large DNS SIG/KEY response analysis with configurable…

Dynamically generated Suricata rules from real-time threat feeds

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

A repository of sysmon configuration modules

Tools for hunting for threats.

Docker configuration to quickly setup your own Canarytokens.

A smart gateway to stop cyber criminals - Sponsored by Falcon Guard

Advanced Phishing Protection: Suricata rulesets open and free

Programmable packet inspection engine with NIDS, DNS classification, frequency analysis, and auto-regex generation. Supports Python/Ruby/Java/Lua…

Zeek package detecting CVE-2022-30216 NTLM relay attacks against Windows Server. Raises notices for exploit attempts and successful exploitation via…

Zero-dependency Windows EDR utility that detects and mitigates unauthorized LSASS memory access, handle duplication, and LOLBin credential dumping in…

Blue Team detection lab created with Terraform and Ansible in Azure.